Data Processing Addendum

This Addendum applies where StackSpend processes personal data on your behalf and you are subject to the GDPR, UK GDPR, the Swiss FADP, or US state privacy laws.

Effective date: 24 August 2026

How this Addendum applies

This Addendum forms part of the Terms of Service and takes effect automatically, without signature, for every customer that uses the Service to process personal data. No separate action is required to rely on it.

If your procurement process requires a signed document, a PDF of this Addendum already signed by ARYNA LTD is available from Settings → Legal & Compliance inside the app, or on request from privacy@stackspend.app. Sign your side and it is fully executed — there is no countersignature to wait for.

This Data Processing Addendum ("Addendum") is entered into between ARYNA LTD, a company registered in England and Wales under company number 17315620 ("StackSpend", "Processor") and the customer entity that has agreed to the Terms of Service ("Customer", "Controller"). Where this Addendum conflicts with the Terms of Service, this Addendum prevails in respect of the processing of personal data.

1. Definitions

"Data Protection Laws" means all laws applicable to the processing of personal data under the Agreement, including Regulation (EU) 2016/679 ("GDPR"); the GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018 together with the Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); and US state privacy laws including the California Consumer Privacy Act as amended ("CCPA").

"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the GDPR.

"Customer Personal Data" means personal data within customer data that StackSpend processes on Customer's behalf, as described in Annex I.

"SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued under section 119A of the Data Protection Act 2018, version B1.0.

"Sub-processor" means a third party engaged by StackSpend to process Customer Personal Data.

2. Roles of the parties

2.1 In respect of Customer Personal Data, Customer is the Controller and StackSpend is the Processor.

2.2 Where Customer is itself a processor acting for a third-party controller, Customer warrants that it has that controller's authority to appoint StackSpend as a sub-processor on these terms.

2.3 StackSpend acts as an independent controller in respect of account administration and billing, security monitoring and fraud prevention carried out for its own compliance purposes, and visitors to its public marketing website. That processing is governed by the Privacy Policy, not by this Addendum.

3. Scope and instructions

3.1 StackSpend processes Customer Personal Data only on Customer's documented instructions, including as to transfers to a third country, unless required to do otherwise by law to which StackSpend is subject. Where StackSpend is so required, it will inform Customer before processing unless the law prohibits it on important grounds of public interest.

3.2 The Terms of Service, this Addendum, and Customer's use of the features and settings of the Service constitute Customer's complete documented instructions.

3.3 StackSpend will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

3.4 Read-only access. Customer supplies read-only credentials for its cloud and AI providers. StackSpend uses those credentials solely to retrieve billing and usage data, and has no write access to Customer's infrastructure or provider accounts.

3.5 Restrictions. StackSpend will not: (a) sell or share Customer Personal Data as those terms are defined under the CCPA; (b) retain, use or disclose Customer Personal Data for any purpose other than performing the Service, or outside the direct business relationship between the parties; (c) combine Customer Personal Data with personal data from another source except as permitted by Data Protection Laws; or (d) use Customer Personal Data, cost or usage data, budgets, reports or dashboard activity for advertising or profiling, or to train machine learning models. StackSpend certifies that it understands and will comply with these restrictions.

4. Confidentiality

StackSpend ensures that persons authorised to process Customer Personal Data are subject to an appropriate obligation of confidentiality, and that access is limited to personnel who require it to deliver the Service.

5. Security

5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, StackSpend implements and maintains the technical and organisational measures set out in Annex II.

5.2 StackSpend may update those measures provided the overall level of security is not materially reduced.

6. Sub-processors

6.1 Customer grants StackSpend general written authorisation to engage sub-processors, subject to this section. The current list is at Annex III and is published at stackspend.app/legal/sub-processors.

6.2 StackSpend will notify Customer of any intended addition or replacement of a sub-processor at least thirty (30) days before that sub-processor begins processing Customer Personal Data, by email to Customer's administrative contact and by updating the published list referred to in section 6.1.

6.3 Customer may object on reasonable data-protection grounds within fifteen (15) days of notification. The parties will work in good faith to resolve the objection. Failing resolution, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the unused remainder of the term.

6.4 StackSpend imposes on each sub-processor data protection obligations no less protective than those in this Addendum, and remains fully liable for each sub-processor's performance.

7. Data subject rights

7.1 Taking into account the nature of the processing, StackSpend assists Customer by appropriate technical and organisational measures, insofar as possible, in meeting Customer's obligation to respond to requests under Chapter III of the GDPR.

7.2 The Service provides self-service access, export, correction and deletion. Where a request cannot be fulfilled through that functionality, StackSpend provides reasonable assistance on request.

7.3 If StackSpend receives a request directly from a data subject relating to Customer Personal Data, it will not respond substantively but will promptly forward the request to Customer, unless legally prohibited.

8. Personal data breach

8.1 StackSpend will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.

8.2 The notification will describe, so far as known, the nature of the breach including the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where information is not available at the time, it will follow in phases without further undue delay.

8.3 StackSpend will reasonably cooperate with and assist Customer in respect of Customer's own notification obligations to supervisory authorities and data subjects.

9. Impact assessments

StackSpend provides reasonable assistance with any data protection impact assessment and prior consultation with a supervisory authority required under Articles 35 and 36 of the GDPR, taking into account the nature of the processing and the information available to StackSpend.

9.2 Costs of assistance

The Service provides self-service functionality for the matters covered by sections 7 and 9. Where Customer requests assistance that goes beyond that functionality and requires material StackSpend effort, StackSpend may charge a reasonable fee based on time spent at its then-current rates, notified to Customer in advance and subject to Customer's approval before the work is undertaken. StackSpend will not charge for assistance required as a result of its own breach of this Addendum.

10. Audit

10.1 StackSpend makes available to Customer the information reasonably necessary to demonstrate compliance with this Addendum.

10.2 StackSpend will respond to a reasonable security questionnaire no more than once per twelve (12) month period, and will make available any third-party audit reports or certifications it then holds.

10.3 Where that information is insufficient, Customer may conduct an audit no more than once per twelve (12) month period, on thirty (30) days' written notice, during business hours, subject to reasonable confidentiality undertakings, and without unreasonably disrupting StackSpend's operations. Customer bears its own costs and StackSpend's reasonable costs. The frequency limit does not apply where a supervisory authority requires an audit. Following a personal data breach affecting Customer Personal Data, Customer may conduct one additional audit in respect of that breach.

11. International transfers

11.1 Customer authorises StackSpend to transfer Customer Personal Data outside the United Kingdom, the European Economic Area and Switzerland — including to the United States, where StackSpend's sub-processors operate — subject to appropriate safeguards.

11.2 EEA transfers. Where Customer Personal Data originating in the EEA is transferred to a country without an adequacy decision, the SCCs (Module Two: Controller to Processor) are incorporated by reference, with: Clause 7 (docking clause) included; Clause 9(a) Option 2 (general written authorisation) applying, with the notice period in section 6.2 above; the optional wording in Clause 11(a) excluded; Clause 17 governed by the law of Ireland; Clause 18(b) specifying the courts of Ireland; and Annexes I, II and III of the SCCs populated by Annexes I, II and III of this Addendum.

11.3 UK transfers. Where Customer Personal Data originating in the UK is transferred, the UK Addendum is incorporated by reference and applies to the SCCs, with Tables 1 to 3 populated by the details in this Addendum and Table 4 selecting "neither party" as the party that may terminate on a change to the Approved Addendum.

11.4 Swiss transfers. Where Customer Personal Data originating in Switzerland is transferred, the SCCs apply with references to the GDPR read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner as the competent authority, and "Member State" read so as not to prevent data subjects in Switzerland from suing in their place of habitual residence.

11.5 If a transfer mechanism relied on under this section is invalidated, the parties will work in good faith to put an alternative lawful mechanism in place without undue delay.

12. Deletion and return

12.1 On termination or expiry of the Agreement, StackSpend will, at Customer's election, delete or return Customer Personal Data and delete existing copies, unless retention is required by law.

12.2 Where Customer makes no election, StackSpend deletes Customer Personal Data in accordance with its published retention practices, and in any event within thirty (30) days of account deletion. This section is subject to sections 12.4, 12.5 and 12.6.

12.3 Customer may export its data through the Service at any time during the term.

12.4 StackSpend may retain Customer Personal Data to the extent required by law, provided it continues to protect that data under this Addendum and processes it only for the purpose of that legal requirement.

12.5 Backups. Customer Personal Data contained in routine backups and point-in-time recovery snapshots is deleted on StackSpend's ordinary backup rotation cycle rather than within the period in section 12.2. Until it is deleted, such data is retained solely for disaster recovery, is isolated from active processing, and remains subject to this Addendum.

12.6 Audit logs. StackSpend retains audit logs for the period stated in Annex I, including after account deletion, as a security and compliance record in its capacity as an independent controller under section 2.3. Audit logs are processed only for that purpose and are permanently deleted at the end of that period.

13. Customer responsibilities

13.1 Customer warrants that: (a) it has a lawful basis for the processing it instructs StackSpend to carry out; (b) it has given all notices and obtained all consents required under Data Protection Laws; (c) its instructions comply with Data Protection Laws; and (d) it will not submit to the Service special category data within the meaning of Article 9 GDPR, criminal offence data within the meaning of Article 10 GDPR, or the personal data of children.

13.2 Customer is responsible for the Customer content it submits to features that transmit that content for automated analysis, as described in Annex III, including source-control correlation and cost-intelligence chat. Customer shall ensure that content submitted to those features is appropriate to be sent for analysis.

13.3 Customer shall indemnify StackSpend against all losses, liabilities and reasonable costs arising from a breach of section 13.1.

14. Liability

Each party's liability under this Addendum is subject to the exclusions and limitations of liability in the Terms of Service.

15. General

15.1 This Addendum takes effect on the effective date above and continues for as long as StackSpend processes Customer Personal Data. Except as amended here, the Terms of Service remain in full force.

15.2 This Addendum is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, except where the SCCs or UK Addendum require otherwise under section 11.

15.3 StackSpend may update this Addendum to reflect changes in Data Protection Laws or its processing operations. Material changes will be notified by email at least thirty (30) days before they take effect, and the current version is always published on this page. This section applies equally to any executed copy of this Addendum, so that a signed copy does not diverge from the current version.

Annex I — Details of processing

Parties

Data exporter (Controller): the Customer entity that has agreed to the Terms of Service. Activity: use of the StackSpend cloud and AI cost management service.

Data importer (Processor): ARYNA LTD. Contact: privacy@stackspend.app. Activity: provision of the StackSpend cloud and AI cost management service.

Categories of data subjects

  • Customer personnel holding StackSpend user accounts (admins and members).
  • Customer personnel appearing in user-level usage data retrieved from connected providers — for example, team member email addresses in per-seat AI tool usage.
  • Customer's billing contact.

Categories of personal data

  • Identity and account: email address, organisation name, role within the organisation.
  • Preferences: timezone, currency.
  • Technical and log: IP address and user agent recorded in audit logs; authentication session data.
  • Usage attribution: provider account and project identifiers, and user-level usage records where the connected provider exposes them.
  • Billing contact: billing email address, and the last four digits and brand of the payment card. Full card numbers are handled by Stripe and are not stored by StackSpend.

Data StackSpend does not receive

StackSpend does not receive, and Customer must not submit to the Service:

  • Customer's own customer, client or end-user data
  • Content from Customer's production systems, databases or applications
  • Special category data within the meaning of Article 9 GDPR
  • Criminal offence data within the meaning of Article 10 GDPR
  • Full payment card numbers (payments are handled by Stripe; StackSpend stores only the last four digits and card brand)
  • Government-issued identifiers

The personal data StackSpend Processes is limited to the workforce identifiers itemised above, which are necessary to authenticate users, operate the service, and attribute cost to the people and teams incurring it. Customer's obligation not to submit the data listed here is set out in clause 13.1.

Nature and purpose of processing

Retrieval, storage, aggregation, analysis and display of Customer's cloud and AI provider billing and usage data; authentication and account management; delivery of transactional notifications (daily cost summaries, budget alerts, anomaly notifications, team invitations); automated categorisation of provider services; currency conversion; anomaly detection; audit logging; and support. Processing is continuous for the duration of the Agreement.

Retention

  • Cost data: for the duration of the active subscription. Monthly aggregates retained while the account is active; daily data retained for at least 12 months.
  • Account data: while the account is active, plus a reasonable period to meet legal obligations.
  • Audit logs: minimum 12 months.
  • Provider credentials: deleted immediately when the provider connection is removed.
  • On account deletion: all associated data permanently removed within 30 days.

Annex II — Technical and organisational measures

  • Encryption at rest. Provider credentials and integration tokens are encrypted using AES-256-GCM, with keys managed separately from application data.
  • Encryption in transit. All connections use TLS. No data is transmitted in cleartext.
  • Tenant isolation. All data is scoped to the customer's organisation by row-level security policies enforced at the database layer. One organisation's data is not accessible to another.
  • Access control. Role-based access within the organisation; authentication sessions managed through secure, httpOnly cookies; internal access to production restricted on a least-privilege basis to personnel who require it.
  • Least-privilege provider access. Integrations request only the permissions needed to read billing data. Credentials are read-only; StackSpend makes no changes to customer infrastructure.
  • Audit logging. Authentication events, provider connection changes, team membership changes and data access are recorded in an immutable audit log retained for a minimum of 12 months.
  • Resilience. Managed database and hosting platforms providing automated backups and point-in-time recovery.
  • Deletion. Provider credentials deleted immediately on removal of a connection; all customer data permanently deleted within 30 days of account deletion.
  • Organisational. Confidentiality obligations on all personnel with access to Customer Personal Data; sub-processors bound by written terms no less protective than this Addendum.

Annex III — Sub-processors

Sub-processorPurposePersonal dataLocation
SupabaseDatabase and authenticationAccount data, cost and usage data, audit logsUnited States
RailwayApplication hosting (API and background workers)Customer Personal Data in transit and in process memoryUnited States
VercelApplication hosting (web frontend)Standard web request dataUnited States
StripePayment processing and subscription managementBilling contact email, subscription detailsUnited States / Ireland
Twilio SendGridTransactional email deliveryRecipient email address, report and alert contentUnited States
OpenAIModel inference for automated classification and cost-intelligence chatProvider service and SKU names; where source-control correlation is enabled, change-request titles, descriptions, labels, changed file paths and diff content; cost-intelligence chat messagesUnited States

Location shown is the sub-processor's country of establishment. Transfers are covered by the safeguards in section 11.

Customer-enabled optional integrations

Where Customer chooses to enable them, cost summaries and alert content are delivered to Slack and Microsoft Teams at Customer's instruction. Customer is responsible for its own relationship with those providers.

What is sent to OpenAI

Automated analysis is performed by a StackSpend-operated service running on the infrastructure already listed above. OpenAI is the only third party in that path, and receives only what is needed for model inference. Three features send data:

  • Service classification. The provider service or SKU name only. No cost amounts, credentials, account identifiers or personal data.
  • Source-control correlation (only where Customer has connected a source-control provider). Change-request titles, descriptions and labels, changed file paths, and diff content for up to 50 files per change, together with the service name and deviation percentage of the related anomaly. Customer should treat this as Customer content and is responsible for ensuring its change descriptions and diffs are appropriate to send for analysis.
  • Cost-intelligence chat (only where Customer uses the feature). The messages Customer sends and the cost context of the question. Conversation history is retained by StackSpend to maintain the thread, within the infrastructure listed above.

Customer Personal Data sent under these features is subject to the restrictions in section 3.5, including the prohibition on training machine learning models.

A note on connected providers

OpenAI appears above as a sub-processor because StackSpend uses it for model inference. This is separate from OpenAI as a provider Customer may connect to StackSpend to read its billing data. Where Customer connects a cloud or AI provider — OpenAI, AWS, Anthropic, Cursor or any other — StackSpend reads data from that provider using credentials Customer supplies. It discloses no Customer Personal Data to them, and they are not sub-processors. Customer's relationship with each connected provider is governed by Customer's own agreement with it.

Not sub-processors

Google Tag Manager and AdRoll / NextRoll operate only on StackSpend's public marketing website, where StackSpend acts as an independent controller. They receive no customer cost data, provider credentials, budgets, reports or dashboard activity, and are not sub-processors of Customer Personal Data.

Contact

Questions about this Addendum, requests for a signed copy, and security questionnaires: privacy@stackspend.app.

See also our Privacy Policy, Security overview, and Terms of Service.

Data Processing Addendum — StackSpend